Protecting AI Applications with Microsoft Sentinel

AI applications introduce new security risks, from prompt injection and malicious content to abuse, excessive resource consumption, and changes to the underlying cloud environment. In this session, we’ll explore how to start protecting AI applications built with Azure OpenAI in Microsoft Foundry by using Azure-native telemetry and Microsoft Sentinel.

Through practical demos, we’ll bring together Foundry Prompt Shields, application telemetry, Azure OpenAI diagnostics, and Azure Activity data to detect prompt attacks, identify repeated malicious behavior, monitor unusual AI usage, create Sentinel analytics rules, and investigate activity across the application and Azure control plane.

We’ll also briefly discuss how this approach can be extended with the broader Microsoft Security stack, including services such as Microsoft Defender for Cloud, Defender XDR, and Microsoft Purview, for organizations that want more integrated posture management, threat protection, investigation, and governance.

The goal is to provide a practical entry point into AI application security and understand what can already be done with Microsoft Sentinel and Azure-native telemetry, then see how the wider Microsoft Security ecosystem can build on that foundation.

Preduslovi za praćenje predavanja / potrebno predznanje
Basic Azure and Sentinel concepts.